ISC2 CC Security Principles Practice Question
A security analyst recommends implementing digital signatures to ensure that a software update has not been altered during distribution. Which aspect of the CIA triad is primarily being addressed?
⚠ Common exam trap
CC often tests the overlap between integrity and non-repudiation for digital signatures, tempting candidates to choose non-repudiation even though the question asks specifically about the CIA triad.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrity
Digital signatures use cryptographic hashing and asymmetric encryption to verify that data has not been altered in transit or at rest, which directly addresses the Integrity pillar of the CIA triad. If even a single bit of the software update changes, the signature verification fails, proving tampering. While signatures also provide authentication and non-repudiation, the question specifically asks which CIA triad aspect is primarily addressed, and integrity is the correct mapping.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Availability
Why it's wrong here
Digital signatures verify integrity and origin, not uptime or service reachability, so availability is untouched by signature verification. Availability controls — redundancy, backups, DDoS mitigation — would be the answer if the requirement were ensuring the update remains accessible to all endpoints during rollout.
- ✗
Confidentiality
Why it's wrong here
Signatures leave the update readable by anyone; they prove integrity and signer identity, not secrecy. Confidentiality would be the answer if the update contents had to be hidden from unauthorised parties, which calls for encryption rather than signing.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation is a by-product of signing, but the scenario's stated goal — detecting alteration in transit — is integrity, the property signatures directly assert. Non-repudiation would be the answer if the requirement were preventing the signer from later denying authorship of the update.
- ✓
Integrity
Why this is correct
Digital signatures use asymmetric cryptography to verify that software updates remain unaltered, detecting any modification between publisher and recipient. This directly addresses integrity, the CIA component concerned with data remaining accurate and trustworthy, rather than confidentiality or availability.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
CIA triad
The CIA triad is a foundational security model that guides organizations in protecting data through confidentiality, integrity, and availability.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.